cbcvebase.

Mozilla Thunderbird vulnerabilities

2,009 known vulnerabilities affecting mozilla/thunderbird.

Total CVEs
2,009
CISA KEV
14
actively exploited
Public exploits
63
Exploited in wild
25
Severity breakdown
CRITICAL666HIGH636MEDIUM667LOW29UNKNOWN11

Vulnerabilities

Page 100 of 101
CVE-2008-5430P4MEDIUMCVSS 4.3v2.0.0.142008-12-13
CVE-2008-5430 [MEDIUM] CVE-2008-5430: Mozilla Thunderbird 2.0.14 does not properly handle (1) multipart/mixed e-mail messages with many MI Mozilla Thunderbird 2.0.14 does not properly handle (1) multipart/mixed e-mail messages with many MIME parts and possibly (2) e-mail messages with many "Content-type: message/rfc822;" headers, which might allow remote attackers to cause a denial of service (stack consumption or other resource consumption) via a large e-mail message, a related issue to CVE-200
nvd
CVE-2012-1964P4MEDIUMCVSS 4.0v5.0v6.0+15 more2012-07-18
CVE-2012-1964 [MEDIUM] CVE-2012-1964: The certificate-warning functionality in browser/components/certerror/content/aboutCertError.xhtml i The certificate-warning functionality in browser/components/certerror/content/aboutCertError.xhtml in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.10 does not properly handle attempted clickjacking of the about:certerror page, which allows man-in-the-
nvd
CVE-2006-3812P4LOWCVSS 2.6v1.5v1.5.0.1+5 more2006-07-29
CVE-2006-3812 [LOW] CVE-2006-3812: Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to reference remote files and possibly load chrome: URLs by tricking the user into copying or dragging links.
nvdosv
CVE-2025-13015P4LOWCVSS 3.4≥ 0, < 1:140.5.0esr-1~deb11u1≥ 0, < 1:140.5.0esr-1~deb12u1+2 more2025-11-11
CVE-2025-13015 [LOW] CVE-2025-13015: Spoofing issue in Firefox Spoofing issue in Firefox. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, Firefox ESR < 115.30, Thunderbird < 145, and Thunderbird < 140.5.
osv
CVE-2005-3402P4LOWCVSS 2.6v1.0.5v1.0.72005-11-01
CVE-2005-3402 [LOW] CVE-2005-3402: The SMTP client in Mozilla Thunderbird 1.0.5 BETA, 1.0.7, and possibly other versions, does not noti The SMTP client in Mozilla Thunderbird 1.0.5 BETA, 1.0.7, and possibly other versions, does not notify users when it cannot establish a secure channel with the server, which allows remote attackers to obtain authentication information without detection via a man-in-the-middle (MITM) attack that bypasses TLS authentication or downgrades CRAM-MD5 authentication to
nvd
CVE-2004-0908P4MEDIUMCVSS 4.0v0.1v0.2+7 more2004-12-31
CVE-2004-0908 [MEDIUM] CVE-2004-0908: Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows untrusted Javascript code to read and write to the clipboard, and possibly obtain sensitive information, via script-generated events such as Ctrl-Ins.
nvd
CVE-2006-2783P4MEDIUMCVSS 4.3≤ 1.5.0.32006-06-02
CVE-2006-2783 [MEDIUM] CWE-79 CVE-2006-2783: Mozilla Firefox and Thunderbird before 1.5.0.4 strip the Unicode Byte-order-Mark (BOM) from a UTF-8 Mozilla Firefox and Thunderbird before 1.5.0.4 strip the Unicode Byte-order-Mark (BOM) from a UTF-8 page before the page is passed to the parser, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a BOM sequence in the middle of a dangerous tag such as SCRIPT.
nvdosv
CVE-2011-2372P4LOWCVSS 3.5≤ 6.0.2v0.1+96 more2011-09-29
CVE-2011-2372 [LOW] CWE-264 CVE-2011-2372: Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not prevent the starting of a download in response to the holding of the Enter key, which allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site.
nvd
CVE-2005-2602P4LOWCVSS 2.6v1.02005-08-17
CVE-2005-2602 [LOW] CVE-2005-2602: Mozilla Thunderbird 1.0 and Firefox 1.0.6 allows remote attackers to obfuscate URIs via a long URI, Mozilla Thunderbird 1.0 and Firefox 1.0.6 allows remote attackers to obfuscate URIs via a long URI, which causes the address bar to go blank and could facilitate phishing attacks.
nvd
CVE-2006-1736P4LOWCVSS 2.6≤ 1.0.7v1.0+7 more2006-04-14
CVE-2006-1736 [LOW] CVE-2006-1736: Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey be Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to trick users into downloading and saving an executable file via an image that is overlaid by a transparent image link that points to the executable, which causes the executable to be saved when the user clicks the "Save image as.
nvd
CVE-2022-42931P4LOWCVSS 3.3≥ 0, < 1:102.4.2+build2-0ubuntu0.18.04.1≥ 0, < 1:102.4.2+build2-0ubuntu0.20.04.1+1 more2022-10-27
CVE-2022-42931 [LOW] CVE-2022-42931: Logins saved by Firefox should be managed by the Password Manager component which uses encryption to save files on-disk Logins saved by Firefox should be managed by the Password Manager component which uses encryption to save files on-disk. Instead, the username (not password) was saved by the Form Manager to an unencrypted file on disk. This vulnerability affects Firefox < 106.
osv
CVE-2012-0475P4LOWCVSS 2.6v5.0v6.0+13 more2012-04-25
CVE-2012-0475 [LOW] CWE-264 CVE-2012-0475: Mozilla Firefox 4.x through 11.0, Thunderbird 5.0 through 11.0, and SeaMonkey before 2.9 do not prop Mozilla Firefox 4.x through 11.0, Thunderbird 5.0 through 11.0, and SeaMonkey before 2.9 do not properly construct the Origin and Sec-WebSocket-Origin HTTP headers, which might allow remote attackers to bypass an IPv6 literal ACL via a cross-site (1) XMLHttpRequest or (2) WebSocket operation involving a nonstandard port number and an IPv6 address that co
nvd
CVE-2005-0148P4MEDIUMCVSS 5.0v0.6v0.7+1 more2005-05-02
CVE-2005-0148 [MEDIUM] CVE-2005-0148: Thunderbird before 0.9, when running on Windows systems, uses the default handler when processing ja Thunderbird before 0.9, when running on Windows systems, uses the default handler when processing javascript: links, which invokes Internet Explorer and may expose the Thunderbird user to vulnerabilities in the version of Internet Explorer that is installed on the user's system. NOTE: since the invocation between multiple products is a common practice, and th
nvd
CVE-2006-1740P4LOWCVSS 2.6≤ 1.0.7v1.0+7 more2006-04-14
CVE-2006-1740 [LOW] CVE-2006-1740: Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey be Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to spoof secure site indicators such as the locked icon by opening the trusted site in a popup window, then changing the location to a malicious site.
nvdosv
CVE-2006-4567P4LOWCVSS 2.6≤ 1.5.0.62006-09-15
CVE-2006-4567 [LOW] CVE-2006-4567: Mozilla Firefox before 1.5.0.7 and Thunderbird before 1.5.0.7 makes it easy for users to accept self Mozilla Firefox before 1.5.0.7 and Thunderbird before 1.5.0.7 makes it easy for users to accept self-signed certificates for the auto-update mechanism, which might allow remote user-assisted attackers to use DNS spoofing to trick users into visiting a malicious site and accepting a malicious certificate for the Mozilla update site, which can then be used to inst
nvdosv
CVE-2006-2786P4LOWCVSS 2.6≤ 1.5.0.32006-06-02
CVE-2006-2786 [LOW] CVE-2006-2786: HTTP response smuggling vulnerability in Mozilla Firefox and Thunderbird before 1.5.0.4, when used w HTTP response smuggling vulnerability in Mozilla Firefox and Thunderbird before 1.5.0.4, when used with certain proxy servers, allows remote attackers to cause Firefox to interpret certain responses as if they were responses from two different sites via (1) invalid HTTP response headers with spaces between the header name and the colon, which might not be ignore
nvdosv
CVE-2008-5503P4LOWCVSS 2.6≤ 2.0.0.18v2.0.0.0+8 more2008-12-17
CVE-2008-5503 [LOW] CVE-2008-5503: The loadBindingDocument function in Mozilla Firefox 2.x before 2.0.0.19, Thunderbird 2.x before 2.0. The loadBindingDocument function in Mozilla Firefox 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 does not perform any security checks related to the same-domain policy, which allows remote attackers to read or access data from other domains via crafted XBL bindings.
nvd
CVE-2006-4570P4LOWCVSS 2.6≤ 1.5.0.62006-09-15
CVE-2006-4570 [LOW] CVE-2006-4570: Mozilla Thunderbird before 1.5.0.7 and SeaMonkey before 1.0.5, with "Load Images" enabled, allows re Mozilla Thunderbird before 1.5.0.7 and SeaMonkey before 1.0.5, with "Load Images" enabled, allows remote user-assisted attackers to bypass settings that disable JavaScript via a remote XBL file in a message that is loaded when the user views, forwards, or replies to the original message.
nvdosv
CVE-2023-34414P4LOWCVSS 3.1fixed in 102.12≥ unspecified, < 102.122023-06-19
CVE-2023-34414 [LOW] CWE-295 CVE-2023-34414: The error page for sites with invalid TLS certificates was missing the activation-delay Firefox uses The error page for sites with invalid TLS certificates was missing the activation-delay Firefox uses to protect prompts and permission dialogs from attacks that exploit human response time delays. If a malicious page elicited user clicks in precise locations immediately before navigating to a site with a certificate error and made the renderer extremel
nvdosv
CVE-2011-3649P4LOWCVSS 2.6v7.02011-11-09
CVE-2011-3649 [LOW] CVE-2011-3649: Mozilla Firefox 7.0 and Thunderbird 7.0, when the Direct2D (aka D2D) API is used on Windows in conju Mozilla Firefox 7.0 and Thunderbird 7.0, when the Direct2D (aka D2D) API is used on Windows in conjunction with the Azure graphics back-end, allow remote attackers to bypass the Same Origin Policy, and obtain sensitive image data from a different domain, by inserting this data into a canvas. NOTE: this issue exists because of a CVE-2011-2986 regression.
nvd
Mozilla Thunderbird vulnerabilities | cvebase